·Insights

"The biggest firms just decided AI assurance is a hire, not a service. That's your opening."

Last week I ran a LinkedIn people-search on "AI assurance Melbourne" and the results told a story. NAB has a Head of AI Assurance. Deloitte has a Partner leading AI Assurance for Australia and a Lead Partner for Trustworthy AI APAC. EY has a Senior Consultant in AI Assurance. IAG has had a Senior Cyber Security Assurance Consultant assessing AI and LLM security risks since June 2021. The biggest firms in the country just decided that AI assurance is a hire, not a service. That's the right call. It's also the reason a 40-person Melbourne business is still going to be asked by its insurer, its bank and its board what its agents can reach — and there will be nobody in the building to answer.

Last week I ran a LinkedIn people-search on "AI assurance Melbourne." The results were stark. NAB has a Head of AI Assurance — a role that didn't exist a year ago. Deloitte has a Partner leading AI Assurance for Australia, a Lead Partner for Trustworthy AI APAC, and a Melbourne-based Trustworthy AI Consultant hired in March 2026. EY has a Senior Consultant in AI Assurance. IAG has had a Senior Cyber Security Assurance Consultant assessing AI and LLM security risks since June 2021.

The independent Melbourne AI-governance consultant lane, by contrast, is empty. The two names that came up — both dormant — were flagged in our research three weeks ago and haven't moved since.

This is the most consequential market shift I've seen in this space. The biggest firms in the country just decided that AI assurance is a hire, not a service. That's the right call for them. It's also the clearest signal about where a boutique like iotasol should position: deliberately below the Big-4 fight, in the sub-200-head tier where nobody is building a function.

The question your board will still ask

Here's what the hire doesn't change. A 40-person Melbourne business — a lender, an insurer, an allied health practice, a logistics firm — is still going to be asked the same questions by its insurer, its bank, its board. What AI tools are your staff using? Who is accountable for each one? What can each agent reach? What happens when it's wrong? Can you stop it?

APRA's April 2026 letter to industry made this explicit. It expects "an inventory of AI tooling and use cases," "ownership and accountability across the AI lifecycle," and internal audit functions that "possess technical capability and tooling to independently assess AI systems including probabilistic models and agentic workflows." The threatened action is enforcement.

The letter was written for banks and insurers. But the expectation cascades. When a small lender's bank asks for its AI inventory, the lender has to produce it. When a logistics firm's insurer asks about automated decision-making, the logistics firm has to answer. The questions don't stop at the regulated entity's door.

The one-page register that answers it

This is the deliverable I keep coming back to. Not a strategy deck. Not a 12-month transformation roadmap. A one-page Agent Accountability Register.

For every AI system or agent the business uses, the register names: a human owner, permitted actions, data classes in scope, prohibited actions, kill criteria with an escalation path, review cadence, and an evidence link. That's it. One page per system. A spreadsheet or a hosted register, not a slide.

We build this as a fixed-fee engagement — A$4,000 to A$7,000, two weeks, dated deliverables, no retainer conversion pressure. It sits deliberately below the A$8,000 readiness-audit floor that Melbourne competitors like Mindiam and Marshall Tech publish. The register is the entry point: once a business has it, the gaps become obvious, and the remediation work scopes itself.

The register also answers the two questions my "scam test" doesn't. Who maintains this when you disappear? The register names the owner. Prove you're competent? The register is the evidence.

Why sovereignty just made this urgent

Last week the ACTU, the UNSW AI Institute, the Australian Institute for Machine Learning in Adelaide, and the Kingston AI Group issued a joint statement arguing Australia should stop depending on offshore frontier models. The ACTU's assistant secretary Joseph Mitchell put it plainly: "The hack of Medicare by OpenAI shows we can't trust our nation's future to US tech bros." Albanese confirmed the government would "engage constructively."

This changes the conversation. "Data stays in Australia" stops being a procurement preference and becomes a national policy argument with a labour-union and academia coalition behind it. For a Melbourne SME, that means the question isn't just "what can our agents reach?" but "where does the model itself run, and who controls it?"

The local-first AI box — open-weight models on your hardware, your documents never leaving the building — is no longer a niche architecture preference. It's the answer to a question the country is now asking out loud.

The through-line

The biggest firms in Australia just internalised AI assurance. That's good for them. It's good for the rest of us too, because it leaves the sub-200-head market — the 40-person lender, the 60-person logistics firm, the allied health practice with twelve clinicians — completely unserved. That's the market worth building for. And it's priced at A$4,000 to A$7,000 for the register, A$15,000 to A$40,000 for the local-first box, not a six-figure retainer.

If you're a Melbourne SME and your board, your insurer or your bank has started asking questions about AI, the first step isn't a strategy deck. It's a register. Happy to walk you through what one looks like.

You Dream, We Build.

Sources

Ravijeet Dang — AI-first business leader. This piece also appears on Substack and LinkedIn.

← All insights